| Cross-Domain Leakage of X Username / UserID due to Dynamically Generated JS File |
Information Disclosure |
th0h0 |
Medium |
2024-05-10 |
| Ability to see hidden likes |
Improper Access Control - Generic |
mirhat |
Medium |
2024-05-10 |
| Bypassing x profile verification to receive instant blue checkmark and unlimited profile changes |
Business Logic Errors |
itsdavid |
Low |
2024-03-26 |
| Able to see Twitter Circle tweets due to improper access control on the "FavoriteTweet" endpoint |
Improper Access Control - Generic |
bugra |
Medium |
2024-03-01 |
| Ability to getting Twitter Blue verified badge without purchase it |
Business Logic Errors |
alp |
Medium |
2024-02-22 |
| Improper santization of edit in list feature at twitter leads to delete any twitter user's list cover photo. |
Insecure Direct Object Reference (IDOR) |
greytesla |
Medium |
2023-09-18 |
| Twitter Subscriptions Information Disclosure |
Information Disclosure |
mirhat |
Medium |
2023-09-18 |
| The Deleted Polls is Still Accessable after 30 Days |
Privacy Violation |
eissen5c |
High |
2023-02-13 |
| Chained open redirects and use of Ideographic Full Stop defeat Twitter's approach to blocking links |
Security Through Obscurity |
jub0bs |
Medium |
2022-12-29 |
| Link-shortener bypass (regression on fix for #1032610) |
Security Through Obscurity |
jub0bs |
Medium |
2022-12-12 |
| Remote 0click exfiltration of Safari user's IP address |
Forced Browsing |
max2x |
Medium |
2022-06-15 |
| Identify the mobile number of a twitter user |
Information Disclosure |
aymen_mansour |
Critical |
2022-03-29 |
| Blind XSS on Twitter's internal Jira panel at ████ allows exfiltration of hackers reports and other sensitive data |
Cross-site Scripting (XSS) - Stored |
iambouali |
Critical |
2022-02-12 |
| Discoverability by phone number/email restriction bypass |
Improper Access Control - Generic |
zhirinovskiy |
High |
2022-02-11 |
| Subdomain takeover of images.crossinstall.com |
Business Logic Errors |
ian |
High |
2022-01-05 |
| PI leakage By Brute Forcing and Phone number deleting without using password |
Improper Access Control - Generic |
a13h1 |
Medium |
2021-04-22 |
| 2 Subdomains Takeover at readfu.com |
Privilege Escalation |
m7mdharoun |
Medium |
2021-03-15 |
| Bypass Password Authentication to Update the Password |
Improper Authentication - Generic |
a13h1 |
Medium |
2021-02-12 |
| Bypass Password Authentication to Update the Password |
Improper Authentication - Generic |
a13h1 |
High |
2021-01-11 |
| iOS app crashed by specially crafted direct message reactions |
Uncontrolled Resource Consumption |
alexiaya |
Medium |
2020-02-21 |
| Stored XSS in https://app.mopub.com |
Cross-site Scripting (XSS) - Stored |
august1808 |
Medium |
2019-12-17 |
| [Twitter Open Source] Releases were & are built/executed/tested/released in the context of insecure/untrusted code |
Cryptographic Issues - Generic |
jlleitschuh |
High |
2019-12-13 |
| Access MoPub Reports Data even after Company removed you from their MoPub Account. |
Information Disclosure |
suyog |
High |
2019-11-05 |
| login csrf in analytics.mopub.com |
Cross-Site Request Forgery (CSRF) |
protostar0 |
Medium |
2019-10-02 |
| Reports Modal in app.mopub.com Disclose by any user |
Information Disclosure |
updatelap |
Medium |
2019-10-02 |
| Periscope-all Firebase database takeover |
Improper Access Control - Generic |
deeptiman |
Critical |
2019-09-25 |
| AppLovin API Key hardcoded in a Github repo |
Cleartext Storage of Sensitive Information |
hackbotone_ |
High |
2019-09-18 |
| Html Injection and Possible XSS via MathML |
Cross-site Scripting (XSS) - Generic |
z41b1337_ |
Critical |
2019-09-03 |
| Wrong Interpretation of URL encoded characters, showing different punny code leads to redirection on different domain |
Open Redirect |
mr_edwards |
Low |
2019-08-26 |
| cookie injection allow dos attack to periscope.tv |
Uncontrolled Resource Consumption |
protostar0 |
Medium |
2019-07-03 |
| Subdomain takeover on dev-admin.periscope.tv |
Privilege Escalation |
h1ch3ro |
Medium |
2019-05-28 |
| HTTPS is not validating TLS mac codes |
Use of a Broken or Risky Cryptographic Algorithm |
cy1337 |
No rating |
2019-05-25 |
| Protected Tweets setting overridden by Android app |
None supplied |
alexiaya |
Low |
2019-05-17 |
| Twitter lite(Android): Vulnerable to local file steal, Javascript injection, Open redirect |
Improper Access Control - Generic |
rahulkankrale |
Critical |
2019-04-29 |
| Protected tweets exposure through the URL |
Information Disclosure |
terjanq |
High |
2019-04-19 |
| Multiple XSS on account settings that can hijack any users in the company. |
Cross-site Scripting (XSS) - Stored |
giddsec |
Critical |
2019-04-01 |
| CSRF on https://www.niche.co leads to "account disconnection" |
Cross-Site Request Forgery (CSRF) |
mik317 |
Medium |
2019-03-02 |
| CSRF and probable account takeover on https://www.niche.co |
Cross-Site Request Forgery (CSRF) |
mik317 |
Medium |
2019-02-28 |
| Information Exposure Through Directory Listing vulnerability on 8 vcache**.usw2.snappytv.com websites |
Information Exposure Through Directory Listing |
ameerpornillos |
Low |
2019-02-11 |
| Tracking of users on third-party websites using the Twitter cookie, due to a flaw in authenticating image requests |
Privacy Violation |
cris-staicu |
Medium |
2019-02-08 |
| [dev.twitter.com] XSS and Open Redirect Protection Bypass |
None supplied |
bywalks |
Medium |
2019-02-07 |
| Incorrect details on OAuth permissions screen allows DMs to be read without permission |
Privacy Violation |
edent |
Medium |
2018-12-14 |
| Opportunity to post hidden comments |
Business Logic Errors |
csanuragjain |
Critical |
2018-12-11 |
| CORS misconfig | Account Takeover |
None supplied |
nahoragg |
High |
2018-12-10 |
| Global defaming of any twitter user |
Business Logic Errors |
csanuragjain |
Critical |
2018-12-06 |